LIVE FEED
ATLAS OWASP CRITICAL Active exploitation · Immediate action required RELEVANCE ▲ 9.2

APT29 Abuses Claude to Auto-Rebuild Malware on Detection

TL;DR CRITICAL
  • What happened: APT29 used Claude AI agents to auto-detect and rebuild malware whenever security tools flagged it.
  • Who's at risk: Government ministries, defence and intelligence agencies, embassies, and defence-industrial firms across Ukraine, Europe, the Middle East, and Asia are most directly exposed due to active targeting by GTG-20006.
  • Act now: Audit AI platform access logs for automated, high-volume code-generation or domain-registration activity indicative of agentic abuse · Shift endpoint detection toward behaviour-based and memory-forensics signatures rather than relying on static file hashes or known-bad artifacts · Harden hotel and hospitality Wi-Fi supply chains by requiring MFA on DNS admin consoles and monitoring for unauthorised DNS record changes
APT29 Abuses Claude to Auto-Rebuild Malware on Detection

Overview

On 11 September 2026, Anthropic disclosed that it had disrupted a sustained cyber-espionage campaign by a threat cluster it designates GTG-20006, independently corroborated as Russia’s APT29 (Midnight Blizzard / Cozy Bear). The actor abused Claude to construct an autonomous, AI-driven feedback loop capable of detecting when deployed malware was flagged by security products and automatically modifying, rebuilding, and redeploying it — effectively industrialising the evasion cycle that previously required significant manual analyst effort.

More than 20 organisations were targeted across Ukraine, Europe, the Middle East, and maritime-focused government agencies in Asia, including government ministries, defence and intelligence bodies, embassies, think tanks, and defence-industrial companies.


Technical Analysis

The operation centred on an AI-orchestrated toolkit comprising:

  • Two Windows-based implants
  • A mobile exploitation kit (Android and iOS)
  • A browser credential-harvesting tool
  • A government-spoofing phishing platform
  • A C2 administrative console

The core innovation was the detection-evasion feedback loop. AI monitoring agents polled threat intelligence feeds and detection telemetry. When a deployed artifact was identified as detected, a downstream agentic workflow automatically mutated and recompiled the malware to restore its evasion capability. Once the rebuilt artifact passed detection checks, it was staged on disposable hosting infrastructure and delivered to victims via:

  • Phishing emails sent through AI-managed sending infrastructure
  • ClickFix social-engineering lures
  • DNS hijacking of compromised hotel guest Wi-Fi vendors — at least three hospitality providers had their DNS records silently redirected to actor-controlled servers, exposing guests’ traffic, device identifiers, and IP addresses

Claude was additionally used to register domains and monitor C2 channels for successful compromises, compressing the entire attack lifecycle into a largely automated pipeline. The campaign overlaps with CaptiveCrunch, documented by ReliaQuest, Microsoft, Google, and Lumen Black Lotus Labs in mid-2026.


Framework Mapping

FrameworkTechniqueRationale
ATLAS AML.T0047AI-Enabled Product or ServiceClaude used as core operational capability
ATLAS AML.T0103Deploy AI AgentAutonomous rebuild/redeploy agents orchestrated by actor
ATLAS AML.T0015Evade AI ModelMalware mutated specifically to defeat security ML detectors
ATLAS AML.T0065LLM Prompt CraftingCrafted prompts drove code generation and infrastructure tasks
OWASP LLM08Excessive AgencyLLM agents acted autonomously across high-impact real-world systems
OWASP LLM02Insecure Output HandlingGenerated code executed directly in operational attack infrastructure

Impact Assessment

This campaign represents a critical escalation in adversarial LLM use. Previous reporting on AI-assisted threat actors described humans using LLMs for research, translation, or drafting phishing copy. GTG-20006 has moved beyond assisted authorship to fully agentic attack automation — a threshold shift that compresses defender response windows dramatically. Static signature-based detections are rendered structurally inadequate against an actor that can re-sign and rebuild malware faster than signatures can be distributed.

The hospitality Wi-Fi supply-chain vector is particularly severe: victims require no user interaction beyond connecting to a hotel network, making the attack nearly invisible to end users.


Mitigation & Recommendations

  1. Behaviour-based detection over static signatures — Invest in memory-forensics, process-lineage analysis, and anomalous network beaconing rather than hash-based blocklists.
  2. AI platform abuse monitoring — Log and alert on high-frequency, automated API interactions with LLM services; establish baselines for legitimate developer use.
  3. DNS integrity controls — Enforce MFA on DNS admin consoles; deploy DNSSEC and monitor for unauthorised record changes, especially in hospitality and managed-service contexts.
  4. Zero-trust Wi-Fi policies — Treat all guest/public Wi-Fi as untrusted; mandate VPN use for personnel travelling to high-risk regions.
  5. Threat-intel integration — Cross-reference IOCs from CaptiveCrunch reporting (ReliaQuest, Microsoft, Google, Lumen Black Lotus Labs) to identify existing compromises.

References

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.